Legal
Privacy policy
What we collect, why we collect it, who else sees it, and how to make us stop.
Last updated 7 October 2026
1. Who is responsible
Marathon Courses is run by Eric Floberg Inc., an Illinois corporation, the data controller for the personal data described here. Registered address: 4001 N. Ravenswood Ave, Unit 602-B, Chicago, IL. Reach us at privacy@hey.marathoncourses.com.
2. What we collect
When you order from the shop
Your name, email, shipping and billing address, and what you bought. Card details go straight to our checkout provider; we never see or store them.
What you put in your basket, and when. Once you give us your email at checkout, we connect your basket and your checkout to it: what was in them, whether you finished, and a link back to a checkout you didn’t, so we can send it to you.
When you buy a course
Our course platform tells us your name, email, what you bought and when, and how far through the lessons you are, so we can see how the courses are used. If your order includes something physical, like the Founder’s Edition journal, the mailing address you give us for it. The course platform takes the payment; we never see your card.
When you use your account and your course
- Signing in: your email, which our sign-in confirms with a one-time code, and a cookie that keeps you signed in.
- Your race: the marathon you pick, or type in, and its date, so the course and the tools can count down to it.
- Our tools: what you enter in a tool inside your course (a recent race time, say), so it can show your results back to you. We keep your latest results, not every keystroke.
- Linking your course to your account: a key kept in your browser on that device, so your course can show your own training. It holds the email you signed in with, runs out after 180 days, and “Unlink this device” removes it.
When you join a list
Your email address and the date you gave it to us. If you sign up for the Base Build, also your first name if you give it, your race and race date, and your answers to its questions, so its emails can count down to your Week 1. If you ask to hear when a poster or a race is ready, which one.
When you contact us
Your name, email and what you write. Our team may use AI tools to help draft a reply; a person on our team checks it before it’s sent, and nothing is sent without that check.
When you browse
A cart cookie so your basket survives a page reload, and standard server logs (IP address, browser, pages requested) kept for security and troubleshooting. If you allow them, analytics and advertising cookies from the companies on our cookie list: the pages you visit, what you click, and roughly where you are, tied to an id in the cookie rather than your name. And your cookie choice itself, with a record of it (see “Cookies and local storage”).
When you come by a partner’s link
Some runners and clubs share links to us as partners, and are paid a share of what the people they send buy (our affiliate program). If you click one, and your cookie choices allow it, we remember which partner sent you for 30 days, so they’re credited if you buy. The partner sees the sale and its amount, never who you are. We also count clicks on partners’ links, without anything that identifies you.
Some partners’ links come with a discount. If you ask for it, you get a code of your own, kept in your browser for 30 days so it’s taken off at checkout without you typing it. We record which partner’s link gave the code out and where it was used, so that partner is credited when you buy with it, whatever your cookie choices, as with any discount code.
When you become a partner
Your name, your email, where and how you’d share your link, and where we pay you; then the clicks, sales and payouts on your link, to run the program and pay you. When we pay you, the payment service you are paid through receives your payout details and the amount. And your tax form, which the law asks us to keep before we pay you: a W-9 (your legal name, address and tax number) or a W-8BEN (the same, with your citizenship and date of birth). It’s encrypted as soon as you send it, and only our team opens it, for our tax records and filings.
When a brand gets in touch
What you send us, through Partner with us or by email (your brand, your name and role, your email and phone, and what you’d like to do with us), to reply to you and, if we work together, to run that. Our team may use AI tools to help draft from our conversation; a person on our team checks it before anything is sent or published. If we get in touch first, it’s at a work address for your brand, from its own site or a business contact directory; tell us and we’ll stop. We keep it while we’re talking or working together, and two years after the last time we were in touch.
When you connect Strava
Only if you choose to, from your account or your course. With your permission on Strava’s own screen, we read through Strava’s API: your activities from the last 120 days, private ones included (name, date, sport, distance, time, pace, climb, heart rate and cadence where recorded, whether it was a race, the shoes you wore, the route’s GPS line, and for a race its full record and recording device); your shoes and their miles; and your name. We read it when you open a page that shows it, press “Sync now”, or Strava tells us an activity changed. Heart rate can count as health data; we read it only because you choose to connect, and you can withdraw by disconnecting.
It is shown only to you, signed in to your account, or in your course once you’ve linked it on that device: never to other members, never shared, sold, used for advertising, combined with other customer data for analysis, or used to train or run AI. It is a short-lived copy: anything read from Strava is deleted within seven days. Disconnect on your account (or remove Marathon Courses at strava.com/settings/apps) and we end our access and delete everything that came from Strava at once, and confirm it on the page. For a copy of what we hold, or to ask for deletion another way, email privacy@hey.marathoncourses.com and we will confirm in writing when it is done.
Strava may monitor and collect data about how our app uses its API (“Usage Data”) and use it for any business purpose, including improving its API and platform, supporting developers and users, and checking that apps comply with its terms. Strava’s own privacy policy covers what Strava does with your data, and wins where the two disagree. Marathon Courses is not made or endorsed by Strava.
3. Why we use it
- To fulfil your order and give you your course: because we need to, to perform our contract with you.
- To email you about your order or your course: same basis.
- To fit the course and the tools to your race: to give you what you signed up for (contract), and only with the details you choose to give us.
- To send you marketing, and the Base Build’s countdown emails: only with your consent, which you can withdraw at any time from any email.
- To remind you about a checkout you didn’t finish: our legitimate interest in helping you complete an order you started. A reminder is only about that checkout, and you can opt out from it.
- To answer you when you write to us: our legitimate interest in helping the people who ask.
- To work with brands: our legitimate interest in finding and running partnerships, and our contract with a brand once we work together.
- To see how the courses are used, and improve them: our legitimate interest in running good courses. This never includes anything from Strava.
- To keep the site working and secure, backups included: our legitimate interest in running a functioning shop.
- To count visits, and to measure and show our ads: with your consent in the EU, the UK and Switzerland, which you can withdraw at any time from “Your privacy choices”; elsewhere, our legitimate interest in knowing what works, and in California you can opt out (see “Your rights”).
- To show you your own running from Strava: only with your consent, which you withdraw by disconnecting.
- To credit and pay our partners: remembering a partner’s link needs your consent in the EU, the UK and Switzerland, like our other advertising cookies; running the program and paying a partner is our contract with them, and keeping their tax form is a legal obligation.
4. Who else sees it
We use a small number of service providers, each acting on our instructions and only for these jobs:
- Our shop and course platforms: checkout and payment, orders, the courses themselves, and your sign-ins
- Hosting, database and backup providers: running the site and keeping our records
- Email providers: our mailing lists, and the emails we send you
- AI tools: helping our team draft replies and summaries, which a person checks before anything is sent or published
- Payment services: paying our partners
- Print and shipping partners: the address on your parcel
- Strava: only if you connect it, the source of your running data, which it holds under its own privacy policy
- Analytics and advertising partners: only the companies named on our cookie list, only while their cookies are on, and only what those cookies collect as you browse, and, from our server, what you buy (below). The large advertising platforms among them also use it for their own purposes, under their own privacy policies.
- Our advisers and the authorities: our accountants and lawyers, and tax and other authorities where the law requires it
You can ask us which companies have handled your data (see “Your rights”). If Marathon Courses is ever sold or merged, your data would pass to the new owner, who would have to keep the promises in this policy; nothing from Strava is ever part of that.
We never sell your personal data for money. When advertising cookies are on, the partners behind them can see what you do on our site so we can measure our ads and show them to you elsewhere, which California and some other states’ laws count as “selling” or “sharing”. When you buy something while they’re on, our server also tells those advertising partners about the purchase, so a sale still counts when an ad blocker or a closed tab stops the cookie: what you bought and what it cost, with your contact details scrambled (hashed) so they can only match them to an account they already have, and the IP address and browser the order came from. With advertising cookies off, none of this goes to them. You can stop it at any time (see “Your rights”). Nothing else you tell us directly goes to them, and nothing from Strava ever does.
5. How long we keep it
- Order and course purchase records: seven years, because tax law requires it.
- Your account, your race and your tool results: while your account is open, or until you ask us to delete them.
- Mailing list and Base Build entries: until you unsubscribe, or ask us to delete them.
- What you put in your basket: 90 days, if you never give us your email. Once you do, your baskets and checkouts are kept with your orders, until you ask us to delete them.
- Support conversations: for now, with no set end date. Ask us and we will delete yours.
- What a brand sends us: two years after we were last in touch.
- Server logs: 90 days.
- Anything read from Strava: seven days at most; your Strava connection until you disconnect.
- The link key in your browser: until you unlink, clear it, or 180 days pass.
- Your cookie choice: a year in your browser, then we ask again. The record that you made it (a random id, where you were, what you chose, when; not your name): two years.
- What we tell advertising partners about a purchase: your details go from our copy after a week; the rest of it (what was bought, when, whether it was sent) after 13 months. A note matching a purchase to your cookie choice: a week.
- Partners’ links and discount codes: 30 days in your browser. Which partner gave out a code, and where it was used: as long as we keep the order it was used on. A note matching a purchase to a partner’s link: 60 days. A sale credited to a partner: seven years, with the order it belongs to. A partner’s own details, their tax form included: while they’re a partner, and seven years after they’re last paid.
- Backups: we keep encrypted backups so we can recover from mistakes or outages. They’re normally deleted after seven days. One set aside to look into a problem is deleted once it’s resolved. Nothing from Strava is ever in them.
6. Where it goes
Our service providers are mostly in the United States and Canada. Where data leaves the UK or the EEA, it goes to a country the UK or the EU recognises as protecting it, or under Standard Contractual Clauses or an equivalent safeguard.
7. Your rights
Depending on where you live you can ask us for a copy of your data, ask us to correct or delete it, object to or restrict how we use it, ask for it in a portable format, and withdraw consent at any time. You can also ask which companies have handled your data. Email privacy@hey.marathoncourses.com and we will respond within 30 days. You can also complain to your national data protection authority.
US residents. Under the privacy laws of California and other states you can ask what personal data we’ve collected about you, and to have it corrected or deleted; if we say no, you can ask us to reconsider. We won’t treat you differently for asking. You can also opt out of the “selling” or “sharing” described in “Who else sees it”: choose “Your privacy choices” at the bottom of any page and turn off advertising, or turn on Global Privacy Control in your browser, which we treat as the same request. It applies to that browser, since those cookies don’t say who you are. The personal data involved is the identifiers in those cookies, what you do on our site and, when you buy something, the purchase with your scrambled contact details, and it goes only to the advertising partners on our cookie list. We don’t knowingly sell or share the data of anyone under 16.
8. Cookies and local storage
Some cookies are needed for the site to work: your basket, keeping you signed in, and remembering your cookie choice. They’re always on. Anything else, analytics and advertising, is listed on our cookie list with who it’s from and how long it stays. In the EU, the UK and Switzerland none of it runs until you say yes; in California you can opt out, and everywhere you can change your mind from “Your privacy choices” at the bottom of any page. We keep a record of each choice, without your name, to show it was made. Inside your course, your browser also keeps the race you picked, the numbers you last used in a tool, and, if you linked your course, its key; they stay on your device. Our checkout and our course platform set their own cookies on their pages, under their own policies.
9. Children
Our shop and courses are not intended for children under 16, and we do not knowingly collect their data.
10. Security
Your data is kept in our own database, reached only by our servers, over encrypted connections. Tax forms and backups are encrypted, keys to other services are never shown in a browser, and staff tools need their own sign-in. If a breach ever puts your data at risk, we will tell you, and anyone the law requires, promptly.
11. Changes
We will update the date at the top of this page when this policy changes, and email list subscribers if the change is material. If we ever want to read more from Strava than section 2 describes, we will ask you first.